Cisco Prime Network Registrar

advertisement
Data Sheet
Cisco® Prime™ Network Registrar®
What’s New in Release 8.0
Cisco Prime Network Registrar Overview
Cisco® Prime™ Network Registrar® is a scalable, high-performance, extensible solution that provides integrated
Domain Name System (DNS), Dynamic Host Configuration Protocol (DHCP), and IP address management (IPAM)
(DDI) services.
The solution includes the following integrated components and their respective services - all supporting both IPv4
and IPv6:
●
A single DHCP server for device network access
●
A single DNS server for IP address translation and service delivery
●
A DNS caching server that supports DNS Security Extensions (DNSSEC) for added DNS security that is
designed to prevent cache poisoning and other attacks
●
A powerful, comprehensive IPAM system to automate and manage all IP address requirements
The Solution Offers
●
Speed and scalability: Blazingly fast, the Cisco Prime Network Registrar DHCP server is also the
industry’s most scalable-supporting 50 million-plus devices in a single customer deployment. The recursive,
extremely fast, Cisco Prime Network Registrar DNS Caching Server offers significant acceleration of DNS
query throughput.
●
Reliability: The solution offers multiple levels of redundancy with DHCP safe failover and support for
High-Availability DNS (HA-DNS). A patent-pending discriminating rate limiter provides unsurpassed
DHCP avalanche prevention to reduce downtime after network outages.
●
Consolidated IPv4/IPv6 address management: Cisco Prime Network Registrar includes
integrated, full lifecycle management for IPv4 and IPv6 and allows dual-stack deployments on a single
server. The full-featured DHCPv6 server provides support for address assignment, both stateless and
stateful configuration, and prefix delegation for full IPv6 address management. The IPAM component helps
ease the transition to IPv6 with the ability to discover and take inventory of IPv4 and IPv6 resources, plan
and model the way an IPv6 network is deployed, and map a current IPv4 network and devices to an IPv6
space.
●
Management complexity minimized with centralization and automation: Cisco Prime Network
Registrar IPAM allows administrators to control and monitor DNS and DHCP servers from a centralized
location, providing a single point of data aggregation and delegation. This helps to synchronize information,
eliminate many manual, time-consuming, and error-prone tasks, and reduce complexity and operating
costs. In addition, with the ability to discover, track, allocate, assign, and reclaim IP addresses
automatically, network operators can easily achieve significant efficiencies. Automation also helps eliminate
IP conflicts and configuration errors, reducing downtime of DHCP and DNS services and lowering network
operating costs.
© 2012 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information.
Page 1 of 4
●
Extensibility: Powerful, industry-leading extension support for both IPv4 and IPv6 allows network operators
to alter and customize DHCP server operations for both IPv4 and IPv6, improving network security, network
performance and third party application integration.
New in Release 8.0
The newest release of Cisco Prime Network Registrar (formerly Cisco Network Registrar) adds these significant
features and benefits:
●
A new, robust IPAM solution: Innovative tools provide centralized, full-lifecycle support of IP addresses,
facilitating easy, integrated management of IPv4 and IPv6 address space, address assignment, and
allocation/reallocation - as well DHCP configurations - all in one solution.
●
DNS caching server: The Cisco Prime Network Registrar DNS caching server improves
speed/performance of high volume recursive queries. The DNS caching server performs DNSSEC
validation, authenticating the origin of DNS data as it transits the network and protecting resource records
against DNS vulnerabilities such as DNS cache poisoning. The DNS caching server also supports DNS64,
providing IPv4 access for hosts with only an IPv6 address.
●
Componentized licensing: Cisco Prime Network Registrar is licensed by component - DHCP, DNS, IPAM,
and DNS Caching are all licensed individually in order to meet different customers’ requirements.
Components can be purchased individually or as one of two suites (DHCP/DNS or DHCP/DNS/IPAM).
Table 1 provides a detailed listing of enhancements and new features of Cisco Prime Network Registrar.
Table 1.
Enhancements and New Features of Cisco Prime Network Registrar
Enhancements and New Features
Description
Benefits
Intuitive GUI
The IPAM module provides a web-based interface
that allows users to associate address blocks easily
with geography, topology, or other user-defined
hierarchies.
Administrators can quickly visualize the network
and allocate addresses based on current and future
requirements. The easy, intuitive GUI provides a
single, comprehensive view of IPv4 and IPv6
addresses.
Planning for hierarchical IPv4 and
IPv6 address space with a
continual feedback loop
IPAM tools facilitate development of a disciplined
IP address plan that can be deployed, monitored
and tracked automatically. Network operators can
plan and stage IP block or subnet allocation, IP
address assignment, addition of a new DHCP pool
and associated parameters.
Enables continuous feedback loop to assure
accuracy and provide an overall management view.
Discovery-to-database reconciliation and exception
reporting helps enable operators to view plan
discrepancies and potential errors or rogue users.
User definability/flexibility and
management of IP address space
A patented container architecture allows the user to
define network-specific topology, address spaces,
domains, device and block types, and associated
attributes. For example, a user can associate
address blocks with geography, topology or other
user-defined hierarchies.
Network administrators can organize address
space in a manner that best matches an
organization’s structure and conforms to policies
and procedures.
Automated address allocation
Automated allocation prevents requiring the
operator to manually enter IP addresses. Simplified
address renumbering allows movement of address
space where it’s needed.
Improves worker productivity and network uptime,
decreasing costs, and allowing service providers
and enterprises to scale seamlessly. Optimal “best
fit” address allocation maximizes address utilization
efficiency.
Automated and manual IP address
and subnet reclaim
When adding a subnet or IP address, automated
Helps ensure that the IP inventory database is
reclaim provides accuracy assurance that what the accurate and helps free up IP addresses or entire
database indicates is “free”- is actually free. The
subnets.
reconciliation action then feeds back to the plan in
terms of adding or changing the database based on
discovered information or the freeing up IP
addresses or subnets through reclaim.
IP Address Planning
© 2012 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information.
Page 2 of 4
Enhancements and New Features
Description
Benefits
Address utilization trending and
forecasting
The IPAM component allows trending and
forecasting of address pools.
Helps to prevent network access failure, calls to the
help desk or customer care, lost revenue and
expensive troubleshooting time.
Automated DHCP Server Configuration
Automated configuration and
advanced support
The IPAM component provides automated DHCP
configuration and support for multitiered
addressing, multihomed hosts (to model multiple IP
addresses on a given device), DHCP client
classes, MAC address processing, client ID, and
more.
Operators can significantly reduce network
downtime with more accurate DHCP
configurations. Advanced configuration support
helps to meet complex network operator needs.
DHCP configuration verification
and preview
The IPAM component provides built-in verification
and preview capabilities.
Helps enable accurate configuration, limiting
network outages and IP conflicts.
Discovery
Cisco Prime Network Registrar IPAM performs host
discovery using a variety of methods including ping,
TCP port 80 connections, DNS lookups, Address
Resolution Protocol (ARP) cache data, and device
OS mapping. Integrated switch port mapping
enbles support of a broad variety of switches.
Router subnet discovery identifies which IPv4 and
IPv6 subnets are provisioned on given router
interfaces. The solution collects rich network data
from a broad variety of multi-vendor Layer 3
routers, Layer 2 switches and DNS/DHCP servers.
Facilitates more accurate address planning and
avoidance of IP addressing conflicts. Collection of
network actual data enables comparison and
reconciliation with the database as well as
resolution of any conflicts. Upon completion of
discovery, administrators also are able to easily
add new devices to the database, identify
unauthorized devices on the network and reclaim
unused IP addresses.
User-defined thresholds and alerts
Users can set up thresholds and alerts - for
example, for notification if an address space is over
a designated utilization percentile or if an address
pool is forecasted to deplete within a designated
time frame.
Proactive management facilitates planning and
helps to minimize network outages and IP conflicts.
Granular administrator policies and
tiered administration capabilities
Granular administrator policies within Cisco Prime
Network Registrar IPAM dictate access to and
visibility and control of given functions,
geographies, domains, subnets and blocks.
Empowers administrators to delineate and partition
responsibilities.
Audit reporting
Audit reporting provides history tracking for
administrators, subnets, devices, IP addresses,
and containers. Inventory reporting shows which
device is assigned to which IP address within the
network at any time.
Promotes accountability.
Multivendor DHCP/DNS support
The IPAM component cohesively supports the
following additional DNS and DHCP servers:
Internet Systems Consortium (ISC DHCP and
BIND 9 DNS) and Microsoft.
Allows support of existing infrastructure.
DNS caching server
The DNS Caching Server component stores DNS
query results locally and performs the actual
recursion to resolve a given name.
Helps to improve efficiency and reduce DNS traffic
across the Internet. Improves the speed and
performance of high-volume recursive queries and
end-user applications.
DNSSEC support
Cisco Prime Network Registrar DNS Caching
Server performs DNSSEC validation and
authenticates the origin of DNS data as it transits
the network.
Helps protect resource records against DNS
vulnerabilities such as DNS cache poisoning.
DNSSEC support also helps to ensure the
authenticity and integrity of DNS records and
servers being accessed and allows compliance for
government agencies where DNSSEC is an
operational mandate.
DNS64 support
The DNS caching server supports DNS64,
synthesizing AAAA (IPv6) records from A (IPv4)
records in order to provide an IPv6-only client
access to an IPv4-only resource.
Helps facilitate the migration of IPv4 to IPv6.
IP Address Management
DNS Enhancements
Componentized Licensing and Purchase Options
New component licensing
The four Cisco Prime Network Registrar
components are all licensed individually.
Components can be purchased individually or as
one of two suites (DHCP/DNS or
DHCP/DNS/IPAM).
© 2012 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information.
Helps meet different customers’ requirements and
provides a cost savings to those who purchase
more than one component.
Page 3 of 4
About Cisco Prime
The Cisco Prime portfolio of enterprise and service provider management offerings empowers IT organizations to
more effectively manage their networks and the services they deliver. Built on a service-centered foundation, the
Cisco Prime portfolio of products supports integrated lifecycle management through an intuitive workflow oriented
user experience. The portfolio of Cisco Prime solutions for service providers provides A-to-Z management for IP
next-generation networks, mobility, video, and managed services.
For more information about Cisco Prime Network Registrar, visit http://www.cisco.com/go/networkregistrar, contact
your local account representative, or send an email to ask-networkregistrar@cisco.com.
Printed in USA
© 2012 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information.
C78-697344-01
02/12
Page 4 of 4
Download